OpenAI has fixed a vulnerability in the macOS version of its ChatGPT app that could have allowed an attacker to take over the application on a victim’s computer. The flaw, discovered by researchers at the Objective-See Foundation, would have given an attacker access to all chat logs and other data stored by the app, along with interconnections such as browser sessions. OpenAI acknowledged the security flaw and the fix in its system change log on September 25.
According to Objective-See Foundation software analyst Patrick Wardle, the ChatGPT macOS app relies on multiple components that verify each other through digital signature checks. These checks are meant to confirm that both processes involved in a request are OpenAI components rather than outside software. The design requires signature verification at three layers removed from a request to prevent malicious software from using an OpenAI component as a proxy.
Wardle found that a trusted script interpreter would accept an untrusted script and could be manipulated to deliver it into the main ChatGPT process. He said the interpreter checks the parent and grandparent of the process, but a malicious script can simply spawn the interpreter three times to satisfy the requirements. Wardle described the vulnerability as trivial to exploit and said his proof of concept required only about a dozen lines of code.
Beyond reading chat logs, the vulnerability could have been used to make ChatGPT run commands on an attacker’s behalf, such as accessing a browser or other sensitive applications. Those requests would appear to be legitimate instructions issued by OpenAI’s software. OpenAI spokesperson Shane Bauer said the company continues to evolve its security practices but recognizes a need to move faster.
Wardle is scheduled to present an analysis of several AI macOS application bugs at Objective by the Sea, an Apple-focused security conference, in November. He also recently found a flaw, since patched, in the dictation feature of Meta’s new Muse AI assistant that could have let a local attacker obtain a mishandled authentication token and reach user data. He said he has submitted a new vulnerability finding to OpenAI concerning the integration between ChatGPT and the company’s new always-on Dots AI assistant, which OpenAI is reviewing.
Wardle said AI companies are focused on adding features, but that more features mean a broader attack surface. In his view, these companies need to concentrate fully on security, and it often still appears to be an afterthought. The incident highlights the system access and trust AI platforms receive in order to function, and the attention that puts on them as targets.
More cybersecurity news from TechManNews.






